Amazon SCS-C02 Exam - Topic 1 Question 47 Discussion
[Infrastructure Security]A Security Engineer is building a Java application that is running on Amazon EC2. The application communicates with an Amazon RDS instance and authenticates with a user name and password.Which combination of steps can the Engineer take to protect the credentials and minimize downtime when the credentials are rotated? (Choose two.)
C) Configure automatic rotation of credentials in AWS Secrets Manager. and E) Configure the Java application to catch a connection failure and make a call to AWS Secrets Manager to retrieve updated credentials when the password is rotated. Grant permission to the instance role associated with the EC2 instance to access Secrets Manager. and E) Configure the Java application to catch a connection failure and make a call to AWS Secrets Manager to retrieve updated credentials when the password is rotated. Grant permission to the instance role associated with the EC2 instance to access Secrets Manager.
By configuring the Java application to catch a connection failure and make a call to AWS Secrets Manager to retrieve updated credentials, you can avoid hard-coding the credentials in your application code or configuration files. This way, your application can dynamically obtain the latest credentials from Secrets Manager whenever the password is rotated, without needing to restart or redeploy the application.To enable this, you need to grant permission to the instance role associated with the EC2 instance to access Secrets Manager using IAM policies2.You can also usethe AWS SDK for Java to integrate your application with Secrets Manager3.
A) Have a Database Administrator encrypt the credentials and store the ciphertext in Amazon S3. Grant permission to the instance role associated with the EC2 instance to read the object and decrypt the ciphertext.
B) Configure a scheduled job that updates the credential in AWS Systems Manager Parameter Store and notifies the Engineer that the application needs to be restarted.
D) Store the credential in an encrypted string parameter in AWS Systems Manager Parameter Store. Grant permission to the instance role associated with the EC2 instance to access the parameter and the AWS KMS key that is used to encrypt it.
Cordelia
7 months agoDenny
7 months agoLizbeth
8 months agoArlyne
8 months agoBarrett
8 months agoEttie
8 months agoGeorgiann
8 months agoArminda
9 months agoIsreal
9 months agoHaydee
9 months agoLeonie
9 months agoCatalina
9 months agoDesirae
10 months agoSarina
11 months agoJonelle
12 months agoPura
10 months agoMelodie
10 months agoMariann
11 months agoRosina
12 months agoMarget
12 months agoMari
12 months agoBok
12 months agoBilly
12 months agoArminda
11 months agoArlette
11 months agoKimberlie
1 year agoAlesia
12 months agoAlpha
12 months agoVesta
1 year agoSarina
1 year ago